Attached is a file 151124142451_0001.xls which I have seen come in two versions so far (VirusTotal results [1][2]). Analysis of this malware is pending, but it most likely leads to the Dridex banking trojan.

UPDATE 1
Automated analysis is inconclusive [1][2][3][4][5][6]. It is possible that there is an error in the macro.

UPDATE 2
According to the comments in this post and also some other sources, the the macros download from: